fw-review

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core review behavior is broadly aligned with the stated purpose and there is no sign of credential theft or exfiltration, but the skill includes low-transparency 'silent' execution and a transitive handoff to an unreviewed `fw-setup` skill for tool installation. Freshworks FDK itself appears to be an official same-publisher dependency, so the main concerns are install trust for the referenced setup skill and reduced user visibility, not confirmed malicious behavior.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
May 14, 2026, 08:53 AM
Package URL
pkg:socket/skills-sh/freshworks-developers%2Ffw-dev-tools%2Ffw-review%2F@c7fadd5e83e312277dc88f16af97c75e39611a53
Security Audit — socket — fw-review